SIG Lite Control TVM-15 Extractive Review Standard

How to answer 'Is source code protected against unauthorized exfiltration?' on a SIG Lite

Reviewer Guidance & Pitfalls

Describe GitHub SSO, mandatory 2FA, IP allowlisting for git access, and disabled public forks.

Example Answer Passing Enterprise Audit

Compliant Response Template
Code repositories enforce SSO with mandatory MFA, disable public repository creation, and audit all clone/download activities (SOC 2, CC6.1).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.